Navigating ICTS Compliance Under Heightened Scrutiny - July 31, 2026 - Geopolitical tensions and the U.S. presidential administration’s desire to bolster national security and keep emerging and critical technology out of the hands of foreign adversaries have intensified scrutiny across the regulatory landscape.1 As a corresponding outcome, Information and Communications Technology and Services (“ICTS”) compliance has emerged as an operational imperative. As a result, organizations must develop an understanding of ICTS requirements and how to build or enhance a compliance program that shifts from reactive to proactive management. Administered by the Office of Information and Communications Technology and Services (“OICTS”) within the U.S. Department of Commerce’s Bureau of Industry and Security (“BIS”), ICTS regulations are intended to prohibit or limit certain transactions that carry national security risks with foreign adversaries, and to secure and ensure the resilience of the ICTS supply chain.2 The core objectives of ICTS regulations are to prevent foreign adversaries from exploiting vulnerabilities in critical infrastructure, compromising the sensitive data of U.S. citizens or American businesses, and using compromised hardware, software, or services to conduct espionage or cyber attacks. Understanding ICTS The definition and applicability of ICTS regulation is broad, encompassing connected vehicles, emerging technologies, and data transmission. To date, key regulations and actions include banning certain antivirus software,3 the connected vehicles rule,4 and Infrastructure as a Service (“IaaS”) requirements for service providers.5 The wide-ranging implications are partially due to both components and end products being subject to ICTS requirements. In other words, component manufacturers and end-product companies are impacted. Further, compliance is an ongoing operational requirement; it extends beyond the deal and is perpetually applicable. The ongoing nature of ICTS regulations means it is especially critical for organizations with a global footprint to possess a comprehensive, proactive compliance program that constantly evaluates risk and determines when